generated: '2026-07-21' method: searched source: https://api.thoropass.com/.well-known/oauth-authorization-server standards: - id: oauth2 conforms: true evidence: 'Published RFC 8414 authorization-server metadata; authorization_code + refresh_token grants' - id: oauth2-pkce-rfc7636 conforms: true evidence: 'code_challenge_methods_supported includes S256' - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: '200 at /.well-known/oauth-authorization-server' - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: '200 at /.well-known/oauth-protected-resource; MCP endpoint returns WWW-Authenticate resource_metadata pointer' - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint published at /oauth/register' - id: rfc7009-token-revocation conforms: true evidence: 'revocation_endpoint published at /oauth/revoke-token/' - id: mcp-model-context-protocol conforms: true evidence: 'Hosted MCP server at api.thoropass.com/mcp with mcp:invoke scope' - id: openid-connect conforms: false evidence: 'No /.well-known/openid-configuration (404); OAuth authorization only, not OIDC' notes: >- Standards asserted from discoverable OAuth/MCP metadata only. Thoropass the product is an auditor for SOC 2, ISO 27001, HIPAA, PCI DSS and HITRUST, but those are frameworks it audits customers against; its own certifications were not machine-verifiable from the (JS-rendered) trust center, so no compliance-program claim is asserted here. See security/thoropass-trust-center.yml.